CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2020-16126

    Last Modified: 21 Nov 2024

    An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stopping it from handling D-Bus messages in a timely fashion.

    Published: 11 Nov 2020
    9.6
    Critical

    CVE-2020-16017

    Last Modified: 24 Oct 2025

    Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 11 Nov 2020
    8.8
    High

    CVE-2020-16013

    Last Modified: 24 Oct 2025

    Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 11 Nov 2020
    8.8
    High

    CVE-2020-25268

    Last Modified: 21 Nov 2024

    Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data.

    Published: 10 Nov 2020
    5.4
    Medium

    CVE-2020-25267

    Last Modified: 21 Nov 2024

    An XSS issue exists in the question-pool file-upload preview feature in ILIAS 6.4.

    Published: 10 Nov 2020
    7.8
    High

    CVE-2020-24367

    Last Modified: 21 Nov 2024

    Incorrect file permissions in BlueStacks 4 through 4.230 on Windows allow a local attacker to escalate privileges by modifying a file that is later executed by a higher-privileged user.

    Published: 10 Nov 2020
    5.4
    Medium

    CVE-2020-28408

    Last Modified: 21 Nov 2024

    The server in Dundas BI through 8.0.0.1001 allows XSS via an HTML label when creating or editing a dashboard.

    Published: 10 Nov 2020
    5.4
    Medium

    CVE-2020-28409

    Last Modified: 21 Nov 2024

    The server in Dundas BI through 8.0.0.1001 allows XSS via addition of a Component (e.g., a button) when events such as click, hover, etc. occur.

    Published: 10 Nov 2020
    7.2
    High

    CVE-2020-24063

    Last Modified: 21 Nov 2024

    The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.

    Published: 10 Nov 2020
    8.8
    High

    CVE-2019-7357

    Last Modified: 21 Nov 2024

    Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.

    Published: 10 Nov 2020
    7.8
    High

    CVE-2020-23968

    Last Modified: 21 Nov 2024

    Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\Ilex\S&G\Logs\000-sngWSService1.log.

    Published: 10 Nov 2020
    —
    Unknown

    CVE-2020-27165

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-28050. Reason: This candidate is a reservation duplicate of CVE-2020-28050. Notes: All CVE users should reference CVE-2020-28050 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Nov 2020
    7.8
    High

    CVE-2020-28055

    Last Modified: 21 Nov 2024

    A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporation allows a local unprivileged attacker, such as a malicious App, to read & write to the /data/vendor/tcl, /data/vendor/upgrade, and /var/TerminalManager directories within the TV file system. An attacker, such as a malicious APK or local unprivileged user could perform fake system upgrades by writing to the /data/vendor/upgrage folder.

    Published: 10 Nov 2020
    5
    Medium

    CVE-2020-27146

    Last Modified: 21 Nov 2024

    The Core component of TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser) contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a Cross Site Request Forgery (CSRF) attack on the affected system. A successful attack using this vulnerability requires human interaction from an authenticated user other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO iProcess Workspace (Browser): versions 11.6.0 and below.

    Published: 10 Nov 2020
    6.5
    Medium

    CVE-2020-27403

    Last Modified: 21 Nov 2024

    A vulnerability in the TCL Android Smart TV series V8-R851T02-LF1 V295 and below and V8-T658T01-LF1 V373 and below by TCL Technology Group Corporation allows an attacker on the adjacent network to arbitrarily browse and download sensitive files over an insecure web server running on port 7989 that lists all files & directories. An unprivileged remote attacker on the adjacent network, can download most system files, leading to serious critical information disclosure. Also, some TV models and/or FW versions may expose the webserver with the entire filesystem accessible on another port. For example, nmap scan for all ports run directly from the TV model U43P6046 (Android 8.0) showed port 7983 not mentioned in the original CVE description, but containing the same directory listing of the entire filesystem. This webserver is bound (at least) to localhost interface and accessible freely to all unprivileged installed apps on the Android such as a regular web browser. Any app can therefore read any files of any other apps including Android system settings including sensitive data such as saved passwords, private keys etc.

    Published: 10 Nov 2020
    9.8
    Critical

    CVE-2020-25074

    Last Modified: 21 Nov 2024

    The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve remote code execution.

    Published: 10 Nov 2020
    3.3
    Low

    CVE-2020-26807

    Last Modified: 21 Nov 2024

    SAP ERP Client for E-Bilanz, version - 1.0, installation sets Incorrect default filesystem permissions are set in its installation folder which allows anyone to modify the files in the folder.

    Published: 10 Nov 2020
    7.5
    High

    CVE-2020-26810

    Last Modified: 21 Nov 2024

    SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request can render the SAP Commerce service itself unavailable leading to Denial of Service with no impact on confidentiality or integrity.

    Published: 10 Nov 2020
    10
    Critical

    CVE-2020-26823

    Last Modified: 21 Nov 2024

    SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Diagnostics Agent Connection Service, this has an impact to the integrity and availability of the service.

    Published: 10 Nov 2020
    10
    Critical

    CVE-2020-26821

    Last Modified: 21 Nov 2024

    SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service, this has an impact to the integrity and availability of the service.

    Published: 10 Nov 2020
    8.8
    High

    CVE-2020-26818

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing authorization, resulting in Information Disclosure.

    Published: 10 Nov 2020
    10
    Critical

    CVE-2020-26824

    Last Modified: 21 Nov 2024

    SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Legacy Ports Service, this has an impact to the integrity and availability of the service.

    Published: 10 Nov 2020
    7.8
    High

    CVE-2020-26817

    Last Modified: 21 Nov 2024

    SAP 3D Visual Enterprise Viewer, version - 9, allows an user to open manipulated HPGL file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.

    Published: 10 Nov 2020
    10
    Critical

    CVE-2020-26822

    Last Modified: 21 Nov 2024

    SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Outside Discovery Configuration Service, this has an impact to the integrity and availability of the service.

    Published: 10 Nov 2020
    4.9
    Medium

    CVE-2020-26814

    Last Modified: 21 Nov 2024

    SAP Process Integration (PGP Module - Business-to-Business Add On), version - 1.0, allows an attacker to read PGP Keys under certain conditions in the PGP Module of Business-to-Business Add-On, these keys can then be used to read messages processed by the module leading to Information Disclosure.

    Published: 10 Nov 2020
    7.2
    High

    CVE-2020-26820

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker who is authenticated as an administrator to use the administrator console, to expose unauthenticated access to the file system and upload a malicious file. The attacker or another user can then use a separate mechanism to execute OS commands through the uploaded file leading to Privilege Escalation and completely compromise the confidentiality, integrity and availability of the server operating system and any application running on it.

    Published: 10 Nov 2020
    8.8
    High

    CVE-2020-26819

    Last Modified: 21 Nov 2024

    SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, that allows them to read and delete database logfiles because of Improper Access Control.

    Published: 10 Nov 2020
    8.6
    High

    CVE-2020-26815

    Last Modified: 21 Nov 2024

    SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network to retrieve sensitive / confidential resources which are otherwise restricted for internal usage only, resulting in a Server-Side Request Forgery vulnerability.

    Published: 10 Nov 2020
    7.2
    High

    CVE-2020-26808

    Last Modified: 21 Nov 2024

    SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions - 101, 102, 103, 104, 105, allows an authenticated attacker to inject arbitrary code into function module leading to code injection that can be executed in the application which affects the confidentiality, availability and integrity of the application.

    Published: 10 Nov 2020
    5.3
    Medium

    CVE-2020-26811

    Last Modified: 21 Nov 2024

    SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request leads to Server Side Request Forgery attack which could lead to retrieval of limited pieces of information about the service with no impact on integrity or availability.

    Published: 10 Nov 2020
    4.3
    Medium

    CVE-2020-6316

    Last Modified: 21 Nov 2024

    SAP ERP and SAP S/4 HANA allows an authenticated user to see cost records to objects to which he has no authorization in PS reporting, leading to Missing Authorization check.

    Published: 10 Nov 2020
    5.3
    Medium

    CVE-2020-26809

    Last Modified: 21 Nov 2024

    SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of sensitive information and impact system configuration confidentiality.

    Published: 10 Nov 2020
    7.5
    High

    CVE-2020-28267

    Last Modified: 21 Nov 2024

    Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution.

    Published: 10 Nov 2020
    7.3
    High

    CVE-2020-7766

    Last Modified: 21 Nov 2024

    This affects all versions of package json-ptr. The issue occurs in the set operation (https://flitbit.github.io/json-ptr/classes/_src_pointer_.jsonpointer.htmlset) when the force flag is set to true. The function recursively set the property in the target object, however it does not properly check the key being set, leading to a prototype pollution.

    Published: 10 Nov 2020
    5.5
    Medium

    CVE-2020-12485

    Last Modified: 21 Nov 2024

    The frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which caused out of the boundary when memory access.The vulnerability eventually leads to a local DOS on the device.

    Published: 10 Nov 2020
    5.4
    Medium

    CVE-2020-4760

    Last Modified: 21 Nov 2024

    IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 188737.

    Published: 10 Nov 2020
    5.4
    Medium

    CVE-2020-4704

    Last Modified: 21 Nov 2024

    IBM Content Navigator 3.0CD is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 187189.

    Published: 10 Nov 2020
    5.5
    Medium

    CVE-2020-4568

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, and 4.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184157.

    Published: 10 Nov 2020
    6.9
    Medium

    CVE-2020-5388

    Last Modified: 21 Nov 2024

    Dell Inspiron 15 7579 2-in-1 BIOS versions prior to 1.31.0 contain an Improper SMM communication buffer verification vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

    Published: 10 Nov 2020
    8.8
    High

    CVE-2020-12321

    Last Modified: 21 Nov 2024

    Improper buffer restriction in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

    Published: 10 Nov 2020
    5.5
    Medium

    CVE-2020-8696

    Last Modified: 21 Nov 2024

    Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 10 Nov 2020
    5.5
    Medium

    CVE-2020-8698

    Last Modified: 21 Nov 2024

    Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

    Published: 10 Nov 2020
    9.8
    Critical

    CVE-2020-24384

    Last Modified: 21 Nov 2024

    A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution (RCE) vulnerability that could be used to compromise affected ACOS systems. ACOS versions 3.2.x (including and after 3.2.2), 4.x, and 5.1.x are affected. aGalaxy versions 3.0.x, 3.2.x, and 5.0.x are affected.

    Published: 10 Nov 2020
    9.8
    Critical

    CVE-2020-0446

    Last Modified: 21 Nov 2024

    There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-168264528

    Published: 10 Nov 2020
    9.8
    Critical

    CVE-2020-0445

    Last Modified: 21 Nov 2024

    There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-168264527

    Published: 10 Nov 2020
    9.8
    Critical

    CVE-2020-0447

    Last Modified: 21 Nov 2024

    There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-168251617

    Published: 10 Nov 2020
    5.5
    Medium

    CVE-2020-0437

    Last Modified: 21 Nov 2024

    In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. This could lead to local denial of service of emergency alerts with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-162741784

    Published: 10 Nov 2020
    8.8
    High

    CVE-2020-0449

    Last Modified: 21 Nov 2024

    In btm_sec_disconnected of btm_sec.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution in the Bluetooth server with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.0 Android-8.1Android ID: A-162497143

    Published: 10 Nov 2020
    7.8
    High

    CVE-2020-0438

    Last Modified: 21 Nov 2024

    In the AIBinder_Class constructor of ibinder.cpp, there is a possible arbitrary code execution due to uninitialized data. This could lead to local escalation of privilege if a process were using libbinder_ndk in a vulnerable way with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-161812320

    Published: 10 Nov 2020
    5.5
    Medium

    CVE-2020-0454

    Last Modified: 21 Nov 2024

    In callCallbackForRequest of ConnectivityService.java, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure of the current SSID with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9Android ID: A-161370134

    Published: 10 Nov 2020